CVE-2026-62917
Microsoft SharePoint Server Spoofing Vulnerability
Description
Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
In plain language
AI Act nowCVE-2026-62917 is a network spoofing flaw in Microsoft SharePoint Server that a low-privileged, logged-in user could misuse to impersonate actions, so most small businesses should patch if they run an affected SharePoint version.
CVE-2026-62917 is an improper input validation vulnerability enabling authenticated request spoofing in Microsoft SharePoint Server via the network, requiring low privileges and user interaction to reach the affected behavior.
What to do now
- Check whether you run Microsoft SharePoint Server 2016, Microsoft SharePoint Server 2019, Microsoft SharePoint Server Subscription Edition, or sharepoint server, and confirm your installed build.
- If your build is older than the fixed versions listed below, schedule an update immediately.
- Update SharePoint to the fixed build for your edition: 16.0.5565.1001 (SharePoint Server 2016), 16.0.10417.20198 (SharePoint Server 2019), or 16.0.19725.20522 (SharePoint Server Subscription Edition / sharepoint server).
- After patching, verify the SharePoint build matches the fixed version and monitor for unusual login or request activity during the next normal usage window.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:RUser InteractionS:UScopeC:LConfidentialityI:LIntegrityA:NAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62917 and every CVE in our database. Create a free account — no credit card required.
Create Free Account